Worm

Worm.Win32.Vobfus.deqm removal instruction

Malware Removal

The Worm.Win32.Vobfus.deqm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.deqm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm.Win32.Vobfus.deqm?


File Info:

name: 787ED932104A2F3C14E6.mlw
path: /opt/CAPEv2/storage/binaries/5a2d3c8dc0789ea5b0f15d563c77fe183e867cbb832dab1193f61097f4d6bd75
crc32: B4838EA7
md5: 787ed932104a2f3c14e619c76f0d625a
sha1: ccda5ecb39d86e937f37d492028e371340c1e764
sha256: 5a2d3c8dc0789ea5b0f15d563c77fe183e867cbb832dab1193f61097f4d6bd75
sha512: 8c1c48712d5f1dfa897651044cdc997be95428bc10902291319ab8202e9d8c0b8d446935c0c282ac4cd38d064354d2498cdee88ef214000e6a26d3f58d872d5f
ssdeep: 3072:HwwQcqsOxjX2IDyG2pfr4GNLzECcKIvMBSYWunCvPQiwhjXH1WkaBx5/lvnjLYar:QwQ3sOx79Ic6OLynWunzXH1W9r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D344B725B254FE2AD51289F0386E9250843FAD321155A80FB9C6BF2933F3F07A155FA7
sha3_384: f4f984989e5b63af71a0f13461d3d446a5fe7680e403b92303cdd8c3be3e1671ebe8b2e848b226e8c0d4f464e16b5021
ep_bytes: 6824474000e8f0ffffff000000000000
timestamp: 2011-12-29 18:54:03

Version Info:

FileVersion: 1.00
Translation: 0x0409 0x04b0

Worm.Win32.Vobfus.deqm also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lsAF
Elasticmalicious (high confidence)
DrWebTrojan.VbCrypt.81
MicroWorld-eScanTrojan.GenericKDZ.92169
ClamAVWin.Trojan.VB-73679
FireEyeGeneric.mg.787ed932104a2f3c
CAT-QuickHealTrojan.Beebone.D
ALYacTrojan.GenericKDZ.92169
MalwarebytesGeneric.Worm.AutoRun.DDS
ZillyaWorm.Vobfus.Win32.1220812
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.85a7a701
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36250.qm0@a021u5pi
CyrenW32/Vobfus.Z.gen!Eldorado
SymantecW32.Changeup
ESET-NOD32a variant of Win32/AutoRun.VB.AQN
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.deqm
BitDefenderTrojan.GenericKDZ.92169
NANO-AntivirusTrojan.Win32.WBNA.cihufr
SUPERAntiSpywareTrojan.Agent/Gen-Otran
AvastWin32:VB-AANK [Trj]
TencentTrojan.Win32.VB.jb
EmsisoftTrojan.GenericKDZ.92169 (B)
F-SecureTrojan.TR/Diple.ecnza
BaiduWin32.Worm.Pronny.d
VIPRETrojan.GenericKDZ.92169
TrendMicroWORM_VOBFUS.SMAB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.dh
SophosW32/VB-FSI
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.92169
JiangminTrojan/Diple.cxzm
AviraTR/Diple.ecnza
MAXmalware (ai score=89)
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D16809
ViRobotTrojan.Win32.A.Diple.270336.A
ZoneAlarmWorm.Win32.Vobfus.deqm
MicrosoftWorm:Win32/Vobfus.gen!R
GoogleDetected
AhnLab-V3Trojan/Win32.Menti.R18663
McAfeeVBObfus.er
TACHYONTrojan/W32.VB-Diple.270336
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMAB
RisingWorm.Pronoy!1.9A2F (CLASSIC)
YandexTrojan.GenAsa!rZdnl2V21sg
IkarusTrojan.Win32.Diple
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBObfus.CM!tr
AVGWin32:VB-AANK [Trj]
DeepInstinctMALICIOUS

How to remove Worm.Win32.Vobfus.deqm?

Worm.Win32.Vobfus.deqm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment